4.3
CVSSv2

CVE-2009-4746

Published: 26/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote malicious users to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.

Vulnerable Product Search on Vulmon Subscribe to Product

dreamlevels dreampoll 3.1

Exploits

During a recent security audit of the DreamPoll 31 software by Dreamlevels, I discovered a number of XSS and SQL Injection vulnerabilities in the application These vulnerabilities could be exploited to make unauthorized changes to a web site or compromise a client accessing a site that utilizes the application Details of the vulnerabilities are ...